70-742 Exam Details

  • Exam Code
    :70-742
  • Exam Name
    :Identity with Windows Server 2016
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :289 Q&As
  • Last Updated
    :Feb 07, 2022

Microsoft 70-742 Online Questions & Answers

  • Question 151:

    You have an enterprise certification authority (CA) named ContosoCA. Recovery agents are configured for ContosoCA.

    You duplicate the User certificate template and name it Cont_User. You plan to issue the certificates based on Cont_User to provide users with the ability to encrypt email messages and files.

    You need to ensure that the recovery agents can access any user-encrypted files and email messages if the users lose their certificate.

    What should you do?

    A. Modify the Recovery Agents settings for ContosoCA.
    B. Issue a certificate based on a key recovery agent certificate.
    C. Modify the Request Handling settings for Cont_User.
    D. On ContosoCA, configure the Key Recovery Agent template as a certificate template to issue.

  • Question 152:

    Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016.

    On Server1, you create a local user named User1. User1 is a member of the local Administrators group.

    Server1 has the following local Group Policies:

    Local Computer Policy Local Computer\User1 Policy Local Computer\Administrators Policy

    You need to force User1 to change his password every 14 days.

    Solution: You configure the Password Policy settings in a Group Policy object (GPO) that is linked to the Domain Controllers organizational unit (OU).

    Does this meet the goal?

    A. Yes
    B. No

  • Question 153:

    Your network contains an Active Directory domain named contoso.com.

    All users are in an organizational unit (OU) named Corp_Users.

    You plan to modify the description of all the users who have a string of 514 in their mobile phone number.

    You need to view a list of the users that will be modified.

    What should you run?

    A. Get-ADOrganizationalUnit-Filter "mobilePhone-Like `*514*' "
    B. Get-ADUser-LDAPFilter "(mobilePhone= `*514*')"
    C. Get-ADUser-Filter "mobilePhone-Like `*514*' "
    D. Get-ADOrganizationalUnit-LDAPFilter "(mobilePhone= `*5514*')"

  • Question 154:

    Your network contains an Active Directory domain named contoso.com. All the accounts of the users in the sales department are in an organizational unit (OU) named SalesOU.

    An application named App1 is deployed to the user accounts in SalesOU by using a Group Policy object (GPO) named Sales GPO.

    You need to set the registry value of \HKEY_CURRENT_USER\Software\App1\Collaboration to 0.

    Solution: You add a user preference that has a Replace action.

    Does this meet the goal?

    A. Yes
    B. No

  • Question 155:

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You deploy a new Active Directory forest.

    You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers. Solution: You configure Kerberos constrained delegation on the computer account of each member server. Does this meet the goal?

    A. Yes
    B. No

  • Question 156:

    You create a user account that will be used as a template for new user accounts.

    Which setting will be copied when you copy the user account from Active Directory Users and Computers?

    A. Published Certificates
    B. the Member of attribute
    C. the Office attribute
    D. the Description attribute
    E. Permissions
    F. Remote Desktop Services Profile

  • Question 157:

    You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA) named CA1.

    You have a test environment that is isolated physically from the corporate network and the Internet.

    You deploy a web server to the test environment. On CA1, you duplicate the Web Server template, and you name the template Web_Cert_Test.

    For the web server, you need to request a certificate that does not contain the revocation information of CA1.

    What should you do first?

    A. From the properties of CA1, allow certificates to be published to the file system.
    B. From the properties of CA1, select Restrict enrollment agents, and then add Web_Cert_Test to the restricted enrollment agent.
    C. From the properties of Web_Cert_Test, assign the Enroll permission to the guest account.
    D. From the properties of Web_Cert_Test, set the Compatibility setting of CA1 to Windows Server 2016.

  • Question 158:

    HOTSPOT

    Your network contains an Active Directory domain named contoso.com. The domain contains the objects shown in the following table.

    Server1 has a local user named Admin1 and a local Group Policy that sets the minimum password length to four characters. The domain has the Group Policy objects (GPOs) shown in the following table.

    What is the minimum password length for each user? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

    Hot Area:

  • Question 159:

    Your network contains an Active Directory domain named contoso.com.

    The domain contains two servers named Server1 and Server2 that run Windows Server 2016.

    Server1 has IP Address Management (IPAM) installed. Server2 has the DHCP Server role installed. The IPAM server retrieves data from Server2.

    The domain has two users named User1 and User2 and a group named Group1. User1 is the only member of Group1.

    Server1 has one IPAM access policy. You edit the access policy as shown in the Policy exhibit. (Click the Exhibit button.)

    The DHCP scopes are configured as shown in the Scopes exhibit. (Click the Exhibit button.)

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.

    Hot Area:

  • Question 160:

    DRAG DROP

    Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2016.

    You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com.

    You deploy Active Directory Federation Services (AD FS) and a Web Application Proxy to the Active Directory domain.

    You need to configure the AD FS deployment to support Azure Multi-Factor Authentication (MFA) as the primary authentication method.

    Which three actions should you perform in sequence on the AD FS server? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Select and Place:

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-742 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.